<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:01:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342351</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342351</link>
      <description>EUVD-2026-342351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342351</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55415</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55415</link>
      <description>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema extensions to reach src/datamodel_code_generator/parser/jsonschema.py and generated import handling through Import.from_full_path and Imports.create_line in src/datamodel_code_generator/imports.py, allowing a newline to break out of an import statement and execute Python code when the generated model is imported. This issue is fixed in version 0.64.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema extensions to reach src/datamodel_code_generator/parser/jsonschema.py and generated import handling through Import.from_full_path and Imports.create_line in src/datamodel_code_generator/imports.py, allowing a newline to break out of an import statement and execute Python code when the generated model is imported. This issue is fixed in version 0.64.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55415</guid>
    </item>
    <item>
      <title>GHSA-5578-w22f-pfx9 — datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import stat…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5578-w22f-pfx9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;The sink is `Import.from_full_path` and `Imports.create_line`:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(&amp;#34;.&amp;#34;)` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&amp;gt; Import:
      split_class_path: list[str] = class_path.split(&amp;#34;.&amp;#34;)
      return cls(import_=split_class_path[-1], from_=&amp;#34;.&amp;#34;.join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;The sink is `Import.from_full_path` and `Imports.create_line`:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(&amp;#34;.&amp;#34;)` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&amp;gt; Import:
      split_class_path: list[str] = class_path.split(&amp;#34;.&amp;#34;)
      return cls(import_=split_class_path[-1], from_=&amp;#34;.&amp;#34;.join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5578-w22f-pfx9</guid>
    </item>
    <item>
      <title>PYSEC-2026-3557 — datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import stat…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;The sink is `Import.from_full_path` and `Imports.create_line`:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(&amp;#34;.&amp;#34;)` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&amp;gt; Import:
      split_class_path: list[str] = class_path.split(&amp;#34;.&amp;#34;)
      return cls(import_=split_class_path[-1], from_=&amp;#34;.&amp;#34;.join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;#### Summary&lt;/p&gt;
&lt;p&gt;A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.&lt;/p&gt;
&lt;p&gt;#### Details&lt;/p&gt;
&lt;p&gt;The sink is `Import.from_full_path` and `Imports.create_line`:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(&amp;#34;.&amp;#34;)` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&amp;gt; Import:
      split_class_path: list[str] = class_path.split(&amp;#34;.&amp;#34;)
      return cls(import_=split_class_path[-1], from_=&amp;#34;.&amp;#34;.join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3557</guid>
    </item>
  </channel>
</rss>
